Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 212

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Trump administration equity stakes pose risks to U.S. companies and markets
First the quarter zip, now a '401(k) mullet' — what Gen Z trends say about the economy
The new Bilt 2.0 cards are open for application. Here's how to decide which card is right for you
Trump’s 'big beautiful bill' may spur significant changes to higher education in 2026 and the rise of 'un-college,' experts say
Epstein files: UK PM Starmer's top aide McSweeney quits over Mandelson scandal
Washington Post publisher Will Lewis announces departure, following mass layoffs
Japanese Prime Minister Takaichi's ruling LDP set to secure supermajority in Lower House: NHK
Goldman Sachs says this under-the-radar biotech play could more than double in value
Epstein files: Congressional lawmakers call for Trump Commerce chief Lutnick to resign, or be fired
Stock futures tick higher as Wall Street awaits closely watched jobs, inflation reports: Live updates